social-engineering

Plan and execute authorized phishing simulations with pretext development and email infrastructure.

Updated Jul 1, 2026
One-click install
npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill social-engineering-bpnrockstar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: social-engineering
Source: https://github.com/bpnrockstar/UnifiedBugHunter/tree/main/skills/social-engineering
Command: npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill social-engineering-bpnrockstar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires gophish, setoolkit, evilginx2, modlishka, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a robust framework for social engineering methodology, enabling security professionals to plan and execute authorized phishing simulations, pretext-driven assessments, and social engineering exercises safely and effectively.

Core Features & Use Cases

  • Pretext Development Framework: Build credible personas and scenarios for phishing and social engineering campaigns.
  • Email Infrastructure: Configure SPF/DKIM/DMARC and utilize phishing tools for email campaigns.
  • Campaign Template: Structure your campaigns with key metrics and contingency plans.
  • Reporting: Document and analyze the outcomes of your campaigns.
  • Use Case: Conduct a targeted phishing simulation against a subset of employees to assess the effectiveness of security awareness training.

Quick Start

Run the 'social-engineering' skill to start the pretext development framework and generate a comprehensive plan for your next security assessment.

Frequently Asked Questions about social-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I develop a credible pretext for an authorized phishing simulation?

To conduct phishing simulations, you must configure SPF, DKIM, and DMARC records for email infrastructure and have access to phishing tools. This setup ensures authorized security assessments execute safely and effectively.

What is the best way to document social engineering campaign results for risk management?

Supported phishing tools include gophish, setoolkit, evilginx2, and modlishka. These dependencies provide the necessary infrastructure to execute email campaigns and phishing simulations within authorized security assessments.

How do I structure a social engineering campaign with contingency plans?

Structuring a social engineering campaign involves using a campaign template that defines key metrics and contingency plans. This ensures authorized testing and pretext-driven assessments are executed with structured risk management.

Does this social engineering methodology require prior email infrastructure setup?

Yes, this social engineering methodology requires configuring email infrastructure like SPF, DKIM, and DMARC. Setting up these authentication protocols is essential before executing authorized phishing simulations.